{"cves":[{"id":"CVE-2009-3459","published":"2009-10-13T10:30:00","updated_at":"2026-05-22T18:09:58.920767+00:00","description":"\nHeap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4,\n8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute\narbitrary code via a crafted PDF file that triggers memory corruption, as\nexploited in the wild in October 2009. NOTE: some of these details are\nobtained from third party information.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3459","https://www.cisa.gov/known-exploited-vulnerabilities-catalog"],"bugs":[""],"patches":{"acroread":[]},"tags":{},"packages":[{"name":"acroread","source":"https://ubuntu.com/security/cve?package=acroread","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=acroread","debian":"https://tracker.debian.org/pkg/acroread","statuses":[{"release_codename":"dapper","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"9.2-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"9.2-1intrepid2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"9.2-1jaunty1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"9.2-1karmic1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2908","published":"2009-10-13T10:30:00","updated_at":"2026-07-04T07:29:49.179418+00:00","description":"\nThe d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux\nkernel 2.6.31 allows local users to cause a denial of service (kernel OOPS)\nand possibly execute arbitrary code via unspecified vectors that cause a\n\"negative dentry\" and trigger a NULL pointer dereference, as demonstrated\nvia a Mutt temporary directory in an eCryptfs mount.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-852-1","https://www.cve.org/CVERecord?id=CVE-2009-2908"],"bugs":["https://bugs.launchpad.net/ecryptfs/+bug/387073","https://bugzilla.redhat.com/show_bug.cgi?id=527534"],"patches":{"linux-source-2.6.15":[],"linux":["break-fix: - 9c2d2056647790c5034d722bd24e9d913ebca73c"]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"2.6.24-25.63","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2.6.27-15.43","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2.6.28-16.55","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.32~rc1","component":null,"pocket":"security"}]},{"name":"linux-source-2.6.15","source":"https://ubuntu.com/security/cve?package=linux-source-2.6.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-source-2.6.15","debian":"https://tracker.debian.org/pkg/linux-source-2.6.15","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.6.32~rc1","component":null,"pocket":"security"}]}],"notices_ids":["USN-852-1"],"notices":[{"id":"USN-852-1","title":"Linux kernel vulnerabilities","summary":"Linux kernel vulnerabilities","instructions":"After a standard system upgrade you need to reboot your computer to\neffect the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed. If\nyou use linux-restricted-modules, you have to update that package as\nwell to get modules which work with the new kernel version. Unless you\nmanually uninstalled the standard kernel metapackages (e.g. linux-generic,\nlinux-server, linux-powerpc), a standard system upgrade will automatically\nperform this as well.\n","references":[],"published":"2009-10-22T00:48:54.233082","description":"Solar Designer discovered that the z90crypt driver did not correctly\ncheck capabilities. A local attacker could exploit this to shut down\nthe device, leading to a denial of service. Only affected Ubuntu 6.06.\n(CVE-2009-1883)\n\nMichael Buesch discovered that the SGI GRU driver did not correctly check\nthe length when setting options. A local attacker could exploit this\nto write to the kernel stack, leading to root privilege escalation or\na denial of service. Only affected Ubuntu 8.10 and 9.04. (CVE-2009-2584)\n\nIt was discovered that SELinux did not fully implement the mmap_min_addr\nrestrictions. A local attacker could exploit this to allocate the\nNULL memory page which could lead to further attacks against kernel\nNULL-dereference vulnerabilities. Ubuntu 6.06 was not affected.\n(CVE-2009-2695)\n\nCagri Coltekin discovered that the UDP stack did not correctly handle\ncertain flags. A local user could send specially crafted commands and\ntraffic to gain root privileges or crash the systeam, leading to a denial\nof service. Only affected Ubuntu 6.06. (CVE-2009-2698)\n\nHiroshi Shimamoto discovered that monotonic timers did not correctly\nvalidate parameters. A local user could make a specially crafted timer\nrequest to gain root privileges or crash the system, leading to a denial\nof service. Only affected Ubuntu 9.04. (CVE-2009-2767)\n\nMichael Buesch discovered that the HPPA ISA EEPROM driver did not\ncorrectly validate positions. A local user could make a specially crafted\nrequest to gain root privileges or crash the system, leading to a denial\nof service. (CVE-2009-2846)\n\nUlrich Drepper discovered that kernel signal stacks were not being\ncorrectly padded on 64-bit systems. A local attacker could send specially\ncrafted calls to expose 4 bytes of kernel stack memory, leading to a\nloss of privacy. (CVE-2009-2847)\n\nJens Rosenboom discovered that the clone method did not correctly clear\ncertain fields. A local attacker could exploit this to gain privileges\nor crash the system, leading to a denial of service. (CVE-2009-2848)\n\nIt was discovered that the MD driver did not check certain sysfs files.\nA local attacker with write access to /sys could exploit this to cause\na system crash, leading to a denial of service. Ubuntu 6.06 was not\naffected. (CVE-2009-2849)\n\nMark Smith discovered that the AppleTalk stack did not correctly\nmanage memory. A remote attacker could send specially crafted traffic\nto cause the system to consume all available memory, leading to a denial\nof service. (CVE-2009-2903)\n\nLoïc Minier discovered that eCryptfs did not correctly handle writing\nto certain deleted files. A local attacker could exploit this to gain\nroot privileges or crash the system, leading to a denial of service.\nUbuntu 6.06 was not affected. (CVE-2009-2908)\n\nIt was discovered that the LLC, AppleTalk, IR, EConet, Netrom, and\nROSE network stacks did not correctly initialize their data structures.\nA local attacker could make specially crafted calls to read kernel memory,\nleading to a loss of privacy. (CVE-2009-3001, CVE-2009-3002)\n\nIt was discovered that the randomization used for Address Space Layout\nRandomization was predictable within a small window of time. A local\nattacker could exploit this to leverage further attacks that require\nknowledge of userspace memory layouts. (CVE-2009-3238)\n\nEric Paris discovered that NFSv4 did not correctly handle file creation\nfailures. An attacker with write access to an NFSv4 share could exploit\nthis to create files with arbitrary mode bits, leading to privilege\nescalation or a loss of privacy. (CVE-2009-3286)\n\nBob Tracy discovered that the SCSI generic driver did not correctly use\nthe right index for array access. A local attacker with write access\nto a CDR could exploit this to crash the system, leading to a denial\nof service. Only Ubuntu 9.04 was affected. (CVE-2009-3288)\n\nJan Kiszka discovered that KVM did not correctly validate certain\nhypercalls. A local unprivileged attacker in a virtual guest could exploit\nthis to crash the guest kernel, leading to a denial of service. Ubuntu\n6.06 was not affected. (CVE-2009-3290)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"linux","version":"2.6.24-25.63","description":"","is_source":true},{"name":"linux-image-2.6.24-25-powerpc64-smp","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-mckinley","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-virtual","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-hppa64","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-sparc64-smp","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-generic","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-lpia","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-powerpc-smp","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-xen","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-hppa32","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-rt","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-386","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-powerpc","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-openvz","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-lpiacompat","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-itanium","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-sparc64","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"},{"name":"linux-image-2.6.24-25-server","version":"2.6.24-25.63","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.24-25.63"}],"dapper":[{"name":"linux-source-2.6.15","version":"2.6.15-55.80","description":"","is_source":true},{"name":"linux-image-2.6.15-55-hppa64","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-mckinley","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-powerpc-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-hppa32-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-686","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-k8","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-server","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-386","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-sparc64-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-k7","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-sparc64","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-server","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-powerpc64-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-hppa32","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-mckinley-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-server-bigiron","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-itanium-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-xeon","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-powerpc","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-amd64-generic","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-hppa64-smp","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"},{"name":"linux-image-2.6.15-55-itanium","version":"2.6.15-55.80","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15","version_link":"https://launchpad.net/ubuntu/+source/linux-source-2.6.15/2.6.15-55.80"}],"intrepid":[{"name":"linux","version":"2.6.27-15.43","description":"","is_source":true},{"name":"linux-image-2.6.27-15-generic","version":"2.6.27-15.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-15.43"},{"name":"linux-image-2.6.27-15-virtual","version":"2.6.27-15.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-15.43"},{"name":"linux-image-2.6.27-15-server","version":"2.6.27-15.43","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.27-15.43"}],"jaunty":[{"name":"linux","version":"2.6.28-16.55","description":"","is_source":true},{"name":"linux-image-2.6.28-16-virtual","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-server","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-ixp4xx","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-lpia","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-versatile","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-iop32x","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-generic","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"},{"name":"linux-image-2.6.28-16-imx51","version":"2.6.28-16.55","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/2.6.28-16.55"}]},"type":"USN","cves_ids":["CVE-2009-3238","CVE-2009-3286","CVE-2009-2848","CVE-2009-3288","CVE-2009-3290","CVE-2009-2698","CVE-2009-3002","CVE-2009-1883","CVE-2009-2903","CVE-2009-2849","CVE-2009-2847","CVE-2009-2584","CVE-2009-2767","CVE-2009-2908","CVE-2009-2846","CVE-2009-2695","CVE-2009-3001"]}]},{"id":"CVE-2009-2699","published":"2009-10-13T10:30:00","updated_at":"2025-07-17T16:42:26.795874+00:00","description":"\nThe Solaris pollset feature in the Event Port backend in poll/unix/port.c\nin the Apache Portable Runtime (APR) library before 1.3.9, as used in the\nApache HTTP Server before 2.2.14 and other products, does not properly\nhandle errors, which allows remote attackers to cause a denial of service\n(daemon hang) via unspecified HTTP requests, related to the prefork and\nevent MPMs.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"does not affect Linux"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2699"],"bugs":[""],"patches":{"apr":[]},"tags":{},"packages":[{"name":"apr","source":"https://ubuntu.com/security/cve?package=apr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apr","debian":"https://tracker.debian.org/pkg/apr","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3591","published":"2009-10-08T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nDopewars 1.5.12 allows remote attackers to cause a denial of service\n(segmentation fault) via a REQUESTJET message with an invalid location.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"fixed in 1.5.12-9 sync"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3591"],"bugs":[""],"patches":{"dopewars":[]},"tags":{},"packages":[{"name":"dopewars","source":"https://ubuntu.com/security/cve?package=dopewars","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dopewars","debian":"https://tracker.debian.org/pkg/dopewars","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.5.12-9","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.5.12-9","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.5.12-9","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.5.12-9","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3589","published":"2009-10-08T15:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nincron 0.5.5 does not initialize supplementary groups when running a\nprocess from a user's incrontabs, which causes the process to be run with\nthe incrond supplementary groups and allows local users to gain privileges\nvia an incrontab table.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://inotify.aiken.cz/?section=incron&page=changelog&lang=en","https://www.cve.org/CVERecord?id=CVE-2009-3589"],"bugs":[""],"patches":{"incron":["vendor: http://cvs.fedoraproject.org/viewvc/rpms/incron/EL-5/incron-0.5.5-initgroups.patch?revision=1.1&view=markup"]},"tags":{},"packages":[{"name":"incron","source":"https://ubuntu.com/security/cve?package=incron","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incron","debian":"https://tracker.debian.org/pkg/incron","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"0.5.7-1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.5.7-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.5.7-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0.5.7-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2948","published":"2009-10-07T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nmount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8\nand 3.4 before 3.4.2, when mount.cifs is installed suid root, does not\nproperly enforce permissions, which allows local users to read part of the\ncredentials file and obtain the password by specifying the path to the\ncredentials file and using the --verbose or -v option.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-839-1","https://www.cve.org/CVERecord?id=CVE-2009-2948"],"bugs":[""],"patches":{"samba":[]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"dapper","status":"released","description":"3.0.22-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.28a-1ubuntu4.9","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2:3.2.3-1ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2:3.3.2-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-839-1"],"notices":[{"id":"USN-839-1","title":"Samba vulnerabilities","summary":"Samba vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-10-01T19:27:34.535160","description":"J. David Hester discovered that Samba incorrectly handled users that lack\nhome directories when the automated [homes] share is enabled. An\nauthenticated user could connect to that share name and gain access to the\nwhole filesystem. (CVE-2009-2813)\n\nTim Prouty discovered that the smbd daemon in Samba incorrectly handled\ncertain unexpected network replies. A remote attacker could send malicious\nreplies to the server and cause smbd to use all available CPU, leading to a\ndenial of service. (CVE-2009-2906)\n\nRonald Volgers discovered that the mount.cifs utility, when installed as a\nsetuid program, would not verify user permissions before opening a\ncredentials file. A local user could exploit this to use or read the\ncontents of unauthorized credential files. (CVE-2009-2948)\n\nReinhard Nißl discovered that the smbclient utility contained format string\nvulnerabilities in its file name handling. Because of security features in\nUbuntu, exploitation of this vulnerability is limited. If a user or\nautomated system were tricked into processing a specially crafted file\nname, smbclient could be made to crash, possibly leading to a denial of\nservice. This only affected Ubuntu 8.10. (CVE-2009-1886)\n\nJeremy Allison discovered that the smbd daemon in Samba incorrectly handled\npermissions to modify access control lists when dos filemode is enabled. A\nremote attacker could exploit this to modify access control lists. This\nonly affected Ubuntu 8.10 and Ubuntu 9.04. (CVE-2009-1886)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"samba","version":"3.0.28a-1ubuntu4.9","description":"","is_source":true},{"name":"smbfs","version":"3.0.28a-1ubuntu4.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.28a-1ubuntu4.9"},{"name":"samba","version":"3.0.28a-1ubuntu4.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.28a-1ubuntu4.9"}],"dapper":[{"name":"samba","version":"3.0.22-1ubuntu3.9","description":"","is_source":true},{"name":"smbfs","version":"3.0.22-1ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.22-1ubuntu3.9"},{"name":"samba","version":"3.0.22-1ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.22-1ubuntu3.9"}],"intrepid":[{"name":"samba","version":"2:3.2.3-1ubuntu3.6","description":"","is_source":true},{"name":"smbclient","version":"2:3.2.3-1ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.2.3-1ubuntu3.6"},{"name":"samba","version":"2:3.2.3-1ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.2.3-1ubuntu3.6"},{"name":"smbfs","version":"2:3.2.3-1ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.2.3-1ubuntu3.6"}],"jaunty":[{"name":"samba","version":"2:3.3.2-1ubuntu3.2","description":"","is_source":true},{"name":"smbfs","version":"2:3.3.2-1ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.3.2-1ubuntu3.2"},{"name":"samba","version":"2:3.3.2-1ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.3.2-1ubuntu3.2"}]},"type":"USN","cves_ids":["CVE-2009-1886","CVE-2009-1888","CVE-2009-2813","CVE-2009-2906","CVE-2009-2948"]}]},{"id":"CVE-2009-2906","published":"2009-10-07T18:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nsmbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and\n3.4 before 3.4.2 allows remote authenticated users to cause a denial of\nservice (infinite loop) via an unanticipated oplock break notification\nreply packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-839-1","https://www.cve.org/CVERecord?id=CVE-2009-2906"],"bugs":[""],"patches":{"samba":[]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"dapper","status":"released","description":"3.0.22-1ubuntu3.9","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"3.0.28a-1ubuntu4.9","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"2:3.2.3-1ubuntu3.6","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"2:3.3.2-1ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-839-1"],"notices":[{"id":"USN-839-1","title":"Samba vulnerabilities","summary":"Samba vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-10-01T19:27:34.535160","description":"J. David Hester discovered that Samba incorrectly handled users that lack\nhome directories when the automated [homes] share is enabled. An\nauthenticated user could connect to that share name and gain access to the\nwhole filesystem. (CVE-2009-2813)\n\nTim Prouty discovered that the smbd daemon in Samba incorrectly handled\ncertain unexpected network replies. A remote attacker could send malicious\nreplies to the server and cause smbd to use all available CPU, leading to a\ndenial of service. (CVE-2009-2906)\n\nRonald Volgers discovered that the mount.cifs utility, when installed as a\nsetuid program, would not verify user permissions before opening a\ncredentials file. A local user could exploit this to use or read the\ncontents of unauthorized credential files. (CVE-2009-2948)\n\nReinhard Nißl discovered that the smbclient utility contained format string\nvulnerabilities in its file name handling. Because of security features in\nUbuntu, exploitation of this vulnerability is limited. If a user or\nautomated system were tricked into processing a specially crafted file\nname, smbclient could be made to crash, possibly leading to a denial of\nservice. This only affected Ubuntu 8.10. (CVE-2009-1886)\n\nJeremy Allison discovered that the smbd daemon in Samba incorrectly handled\npermissions to modify access control lists when dos filemode is enabled. A\nremote attacker could exploit this to modify access control lists. This\nonly affected Ubuntu 8.10 and Ubuntu 9.04. (CVE-2009-1886)\n","is_hidden":false,"release_packages":{"hardy":[{"name":"samba","version":"3.0.28a-1ubuntu4.9","description":"","is_source":true},{"name":"smbfs","version":"3.0.28a-1ubuntu4.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.28a-1ubuntu4.9"},{"name":"samba","version":"3.0.28a-1ubuntu4.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.28a-1ubuntu4.9"}],"dapper":[{"name":"samba","version":"3.0.22-1ubuntu3.9","description":"","is_source":true},{"name":"smbfs","version":"3.0.22-1ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.22-1ubuntu3.9"},{"name":"samba","version":"3.0.22-1ubuntu3.9","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/3.0.22-1ubuntu3.9"}],"intrepid":[{"name":"samba","version":"2:3.2.3-1ubuntu3.6","description":"","is_source":true},{"name":"smbclient","version":"2:3.2.3-1ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.2.3-1ubuntu3.6"},{"name":"samba","version":"2:3.2.3-1ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.2.3-1ubuntu3.6"},{"name":"smbfs","version":"2:3.2.3-1ubuntu3.6","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.2.3-1ubuntu3.6"}],"jaunty":[{"name":"samba","version":"2:3.3.2-1ubuntu3.2","description":"","is_source":true},{"name":"smbfs","version":"2:3.3.2-1ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.3.2-1ubuntu3.2"},{"name":"samba","version":"2:3.3.2-1ubuntu3.2","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.3.2-1ubuntu3.2"}]},"type":"USN","cves_ids":["CVE-2009-1886","CVE-2009-1888","CVE-2009-2813","CVE-2009-2906","CVE-2009-2948"]}]},{"id":"CVE-2009-3579","published":"2009-10-07T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nCross-site scripting (XSS) vulnerability in the CookieDump.java sample\napplication in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackers to\ninject arbitrary web script or HTML via the Value parameter in a GET\nrequest to cookie/.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"in a sample application"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3579"],"bugs":[""],"patches":{"jetty":[]},"tags":{},"packages":[{"name":"jetty","source":"https://ubuntu.com/security/cve?package=jetty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jetty","debian":"https://tracker.debian.org/pkg/jetty","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"6.1.22-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"6.1.22-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"6.1.22-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"6.1.22-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.1.21","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3575","published":"2009-10-07T17:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3, 1.2.0,\nand other versions allows remote attackers to cause a denial of service\n(crash) and possibly execute arbitrary code via unknown vectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3575"],"bugs":[""],"patches":{"aria2":[]},"tags":{},"packages":[{"name":"aria2","source":"https://ubuntu.com/security/cve?package=aria2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=aria2","debian":"https://tracker.debian.org/pkg/aria2","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.18.1-1","component":null,"pocket":"security"},{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"quantal","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"raring","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"saucy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"1.18.1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.0-1","component":null,"pocket":"security"},{"release_codename":"utopic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"1.18.1-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3571","published":"2009-10-06T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in OpenOffice.org (OOo) has unknown impact and\nclient-side attack vector, as demonstrated by a certain module in VulnDisco\nPack Professional 8.8, aka \"Client-side exploit.\" NOTE: as of 20091005,\nthis disclosure has no actionable information. However, because the\nVulnDisco Pack author is a reliable researcher, the issue is being assigned\na CVE identifier for tracking purposes.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"not enough information to do anything. Defer until more information\nbecomes available"},{"author":"mdeslaur","note":"still no info as of 2010-11-11"},{"author":"jdstrand","note":"still no info as of 2011-10-06. Marking as ignored. Can reopen when\nmore info is available."}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3571"],"bugs":[""],"patches":{"openoffice.org":[],"libreoffice":[]},"tags":{},"packages":[{"name":"libreoffice","source":"https://ubuntu.com/security/cve?package=libreoffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libreoffice","debian":"https://tracker.debian.org/pkg/libreoffice","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openoffice.org","source":"https://ubuntu.com/security/cve?package=openoffice.org","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org","debian":"https://tracker.debian.org/pkg/openoffice.org","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"transitional package","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3570","published":"2009-10-06T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nUnspecified vulnerability in OpenOffice.org (OOo) has unspecified impact\nand remote attack vectors, as demonstrated by a certain module in VulnDisco\nPack Professional 8.9. NOTE: as of 20091005, this disclosure has no\nactionable information. However, because the VulnDisco Pack author is a\nreliable researcher, the issue is being assigned a CVE identifier for\ntracking purposes.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"not enough information to do anything. Defer until more information\nbecomes available"},{"author":"mdeslaur","note":"still no info as of 2010-11-11"},{"author":"jdstrand","note":"still no information as of 2011-10-06. Ignoring until further\ninformation"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3570"],"bugs":[""],"patches":{"openoffice.org":[],"libreoffice":[]},"tags":{},"packages":[{"name":"libreoffice","source":"https://ubuntu.com/security/cve?package=libreoffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libreoffice","debian":"https://tracker.debian.org/pkg/libreoffice","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openoffice.org","source":"https://ubuntu.com/security/cve?package=openoffice.org","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org","debian":"https://tracker.debian.org/pkg/openoffice.org","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"transitional package","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3569","published":"2009-10-06T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nStack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers\nto execute arbitrary code via unspecified vectors, as demonstrated by a\ncertain module in VulnDisco Pack Professional 8.8, aka \"Client-side stack\noverflow exploit.\" NOTE: as of 20091005, this disclosure has no actionable\ninformation. However, because the VulnDisco Pack author is a reliable\nresearcher, the issue is being assigned a CVE identifier for tracking\npurposes.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"not enough information to do anything. Defer until more information\nbecomes available"},{"author":"mdeslaur","note":"still no info as of 2010-11-11, also probably mitigated by\nstack protector, downgrading to low"},{"author":"jdstrand","note":"still no information. Due to stack overflow, marking as protected\n(just a crasher) and ignoring. Can reopen once more info is available"}],"codename":null,"priority":"negligible","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3569"],"bugs":[""],"patches":{"openoffice.org":[],"libreoffice":[]},"tags":{"openoffice.org":["stack-protector"],"libreoffice.org":["stack-protector"]},"packages":[{"name":"libreoffice","source":"https://ubuntu.com/security/cve?package=libreoffice","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libreoffice","debian":"https://tracker.debian.org/pkg/libreoffice","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"openoffice.org","source":"https://ubuntu.com/security/cve?package=openoffice.org","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openoffice.org","debian":"https://tracker.debian.org/pkg/openoffice.org","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"transitional package","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3568","published":"2009-10-06T20:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nComment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for Drupal,\ndoes not properly enforce permissions when a link is added to the RSS feed,\nwhich allows remote attackers to obtain the node title and possibly other\nsensitive content by reading the feed.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"drupal packages don't contain commentRSS"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["http://drupal.org/node/579280","https://www.cve.org/CVERecord?id=CVE-2009-3568"],"bugs":[""],"patches":{"drupal5":[],"drupal6":[]},"tags":{},"packages":[{"name":"drupal5","source":"https://ubuntu.com/security/cve?package=drupal5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal5","debian":"https://tracker.debian.org/pkg/drupal5","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"drupal6","source":"https://ubuntu.com/security/cve?package=drupal6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=drupal6","debian":"https://tracker.debian.org/pkg/drupal6","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3564","published":"2009-10-06T00:00:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\npuppetmasterd in puppet 0.24.6 does not reset supplementary groups when it\nswitches to a different user, which might allow local users to access\nrestricted files.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"reproducer in upstream bug\nupstream has not fixed this in 0.24.x as of 2010-03-17"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-917-1","https://www.cve.org/CVERecord?id=CVE-2009-3564"],"bugs":["http://projects.reductivelabs.com/issues/1806","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=551073","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3564"],"patches":{"puppet":["upstream: http://projects.reductivelabs.com/projects/puppet/repository/revisions/e32f980fd7c6291abc2841ede397c962798d9a9c/diff"]},"tags":{},"packages":[{"name":"puppet","source":"https://ubuntu.com/security/cve?package=puppet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=puppet","debian":"https://tracker.debian.org/pkg/puppet","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"released","description":"0.24.8-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"0.25.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"0.25.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"0.25.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"0.25.4-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-917-1"],"notices":[{"id":"USN-917-1","title":"Puppet vulnerabilities","summary":"Puppet vulnerabilities","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2010-03-24T12:40:48.566973","description":"It was discovered that Puppet did not drop supplementary groups when being\nrun as a different user. A local user may be able to use this flaw to\nbypass security restrictions and gain access to restricted files.\n(CVE-2009-3564)\n\nIt was discovered that Puppet did not correctly handle temporary files. A\nlocal user can exploit this flaw to bypass security restrictions and\noverwrite arbitrary files. (CVE-2010-0156)\n","is_hidden":false,"release_packages":{"karmic":[{"name":"puppet","version":"0.24.8-2ubuntu4.1","description":"","is_source":true},{"name":"puppet","version":"0.24.8-2ubuntu4.1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/puppet","version_link":"https://launchpad.net/ubuntu/+source/puppet/0.24.8-2ubuntu4.1"}]},"type":"USN","cves_ids":["CVE-2010-0156","CVE-2009-3564"]}]},{"id":"CVE-2009-3525","published":"2009-10-05T19:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nThe pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support\nthe password option in grub.conf for para-virtualized guests, which allows\nattackers with access to the para-virtualized guest console to boot the\nguest or modify the guest's kernel boot parameters without providing the\nexpected password.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3525"],"bugs":[""],"patches":{"xen-3.1":[],"xen-3.2":[],"xen-3.3":[],"xen":[]},"tags":{"xen-3.1":["universe-binary"],"xen-3.2":["universe-binary"],"xen-3.3":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"dapper","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.1","source":"https://ubuntu.com/security/cve?package=xen-3.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen-3.1","debian":"https://tracker.debian.org/pkg/xen-3.1","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.2","source":"https://ubuntu.com/security/cve?package=xen-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen-3.2","debian":"https://tracker.debian.org/pkg/xen-3.2","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"xen-3.3","source":"https://ubuntu.com/security/cve?package=xen-3.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen-3.3","debian":"https://tracker.debian.org/pkg/xen-3.3","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-2904","published":"2009-10-01T15:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nA certain Red Hat modification to the ChrootDirectory feature in OpenSSH\n4.8, as used in sshd in OpenSSH 4.3 in Red Hat Enterprise Linux (RHEL) 5.4\nand Fedora 11, allows local users to gain privileges via hard links to\nsetuid programs that use configuration files within the chroot directory,\nrelated to requirements for directory ownership.","ubuntu_description":"","notes":[{"author":"kees","note":"RedHat-specific"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-2904"],"bugs":[""],"patches":{"openssh":[]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"dapper","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3490","published":"2009-09-30T15:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nGNU Wget before 1.12 does not properly handle a '\\0' character in a domain\nname in the Common Name field of an X.509 certificate, which allows\nman-in-the-middle remote attackers to spoof arbitrary SSL servers via a\ncrafted certificate issued by a legitimate Certification Authority, a\nrelated issue to CVE-2009-2408.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-842-1","https://www.cve.org/CVERecord?id=CVE-2009-3490"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=549293","http://savannah.gnu.org/bugs/?27183 (no public)"],"patches":{"wget":["upstream: http://hg.addictivecode.org/wget/mainline/rev/2d8c76a23e7d","upstream: http://hg.addictivecode.org/wget/mainline/rev/f2d2ca32fd1b","upstream: http://hg.addictivecode.org/wget/mainline/rev/1eab157d3be7"]},"tags":{},"packages":[{"name":"wget","source":"https://ubuntu.com/security/cve?package=wget","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wget","debian":"https://tracker.debian.org/pkg/wget","statuses":[{"release_codename":"dapper","status":"released","description":"1.10.2-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"hardy","status":"released","description":"1.10.2-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.11.4-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.11.4-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12","component":null,"pocket":"security"}]}],"notices_ids":["USN-842-1"],"notices":[{"id":"USN-842-1","title":"Wget vulnerability","summary":"Wget vulnerability","instructions":"In general, a standard system upgrade is sufficient to effect the\nnecessary changes.\n","references":[],"published":"2009-10-06T17:09:20.034267","description":"It was discovered that Wget did not correctly handle SSL certificates with\nzero bytes in the Common Name. A remote attacker could exploit this to\nperform a machine-in-the-middle attack to view sensitive information or alter\nencrypted communications.\n","is_hidden":false,"release_packages":{"dapper":[{"name":"wget","version":"1.10.2-1ubuntu1.1","description":"","is_source":true},{"name":"wget","version":"1.10.2-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.10.2-1ubuntu1.1"}],"hardy":[{"name":"wget","version":"1.10.2-3ubuntu1.1","description":"","is_source":true},{"name":"wget","version":"1.10.2-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.10.2-3ubuntu1.1"}],"intrepid":[{"name":"wget","version":"1.11.4-1ubuntu1.1","description":"","is_source":true},{"name":"wget","version":"1.11.4-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.11.4-1ubuntu1.1"}],"jaunty":[{"name":"wget","version":"1.11.4-2ubuntu1.1","description":"","is_source":true},{"name":"wget","version":"1.11.4-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wget","version_link":"https://launchpad.net/ubuntu/+source/wget/1.11.4-2ubuntu1.1"}]},"type":"USN","cves_ids":["CVE-2009-3490"]}]},{"id":"CVE-2009-3476","published":"2009-09-29T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nBuffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth\nService Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2\nas used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1,\nallows remote attackers to cause a denial of service and possibly execute\narbitrary code via a malformed encoded URL.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3476"],"bugs":[""],"patches":{"shibboleth-sp":[],"opensaml":[],"xmltooling":[]},"tags":{},"packages":[{"name":"opensaml","source":"https://ubuntu.com/security/cve?package=opensaml","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=opensaml","debian":"https://tracker.debian.org/pkg/opensaml","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.1-2+lenny1build0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.1-2+lenny1build0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.3","component":null,"pocket":"security"}]},{"name":"shibboleth-sp","source":"https://ubuntu.com/security/cve?package=shibboleth-sp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=shibboleth-sp","debian":"https://tracker.debian.org/pkg/shibboleth-sp","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.3.1.dfsg1-3+lenny1build0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.4","component":null,"pocket":"security"}]},{"name":"xmltooling","source":"https://ubuntu.com/security/cve?package=xmltooling","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xmltooling","debian":"https://tracker.debian.org/pkg/xmltooling","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.0-2+lenny1build0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0-2+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.2.2-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.2-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.2-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3475","published":"2009-09-29T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nInternet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x\nbefore 2.2.1, when using PKIX trust validation, does not properly handle a\n'\\0' character in the subject or subjectAltName fields of a certificate,\nwhich allows remote man-in-the-middle attackers to spoof arbitrary SSL\nservers via a crafted certificate issued by a legitimate Certification\nAuthority, a related issue to CVE-2009-2408.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3475"],"bugs":[""],"patches":{"shibboleth-sp":[],"opensaml":[],"xmltooling":[]},"tags":{},"packages":[{"name":"opensaml","source":"https://ubuntu.com/security/cve?package=opensaml","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=opensaml","debian":"https://tracker.debian.org/pkg/opensaml","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.1-2+lenny1build0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.1-2+lenny1build0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"shibboleth-sp","source":"https://ubuntu.com/security/cve?package=shibboleth-sp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=shibboleth-sp","debian":"https://tracker.debian.org/pkg/shibboleth-sp","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.3.1.dfsg1-3+lenny1build0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.3, 2.2.1","component":null,"pocket":"security"}]},{"name":"xmltooling","source":"https://ubuntu.com/security/cve?package=xmltooling","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xmltooling","debian":"https://tracker.debian.org/pkg/xmltooling","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.2.2-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.2-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.2-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2009-3474","published":"2009-09-29T23:30:00","updated_at":"2024-07-24T15:57:39.284958+00:00","description":"\nOpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by\nInternet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the\nKeyDescriptor element's Use attribute, which allows remote attackers to use\na certificate for both signing and encryption when it is designated for\njust one purpose, potentially weakening the intended security application\nof the certificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2009-3474"],"bugs":[""],"patches":{"shibboleth-sp":[],"opensaml":[],"xmltooling":[]},"tags":{},"packages":[{"name":"opensaml","source":"https://ubuntu.com/security/cve?package=opensaml","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=opensaml","debian":"https://tracker.debian.org/pkg/opensaml","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.1.1-2+lenny1build0.8.10.2","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.1.1-2+lenny1build0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.1","component":null,"pocket":"security"}]},{"name":"shibboleth-sp","source":"https://ubuntu.com/security/cve?package=shibboleth-sp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=shibboleth-sp","debian":"https://tracker.debian.org/pkg/shibboleth-sp","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.3.1.dfsg1-3+lenny1build0.9.04.2","component":null,"pocket":"security"},{"release_codename":"karmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lucid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"maverick","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"natty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.1","component":null,"pocket":"security"}]},{"name":"xmltooling","source":"https://ubuntu.com/security/cve?package=xmltooling","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xmltooling","debian":"https://tracker.debian.org/pkg/xmltooling","statuses":[{"release_codename":"dapper","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hardy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"intrepid","status":"released","description":"1.0-2+lenny1build0.8.10.1","component":null,"pocket":"security"},{"release_codename":"jaunty","status":"released","description":"1.0-2+lenny1build0.9.04.1","component":null,"pocket":"security"},{"release_codename":"karmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lucid","status":"not-affected","description":"1.2.2-1","component":null,"pocket":"security"},{"release_codename":"maverick","status":"not-affected","description":"1.2.2-1","component":null,"pocket":"security"},{"release_codename":"natty","status":"not-affected","description":"1.2.2-1","component":null,"pocket":"security"},{"release_codename":"oneiric","status":"not-affected","description":"1.2.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":73640,"limit":20,"total_results":79316}